Director – Security Architect

Cephas Consultancy Services Private Limited

Bengaluru

On-site

INR 5,000,000 - 9,500,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cephas Consultancy Services Private Limited seeks an experienced Director-level Security Architect to lead design, governance, and delivery of large-scale security transformations for a global client. The role combines hands-on configuration with strategic oversight, including Microsoft Entra ID, Defender, and Purview deployments, and high‑level client relationship management with CISOs and boards.

You will mentor teams and drive wave-based rollout governance to ensure regulatory compliance

Qualifications

  • 15+ years in cybersecurity and 8+ years in enterprise security architecture.

Responsibilities

  • Hands-On Architecture Leadership & Delivery: Own end-to-end target security architecture across Microsoft Entra ID, Defender Suite, Purview; configure CA, Identity Protection, DLP and labels.

Skills

Microsoft E5 Security
Entra ID
Defender Suite
Purview DLP
RBAC
XDR integration
DLP design
CISO presentation
Stakeholder mgmt
Hands-on delivery

Tools

CrowdStrike
Checkpoint
Symantec DLP
Sophos

Job description

About this position

We are an IT Consulting Organization based out of Bhubaneswar, Bangalore & assisting our clients in finding suitable manpower PAN India for FTE & Contractual positions.

Payroll -

Please go through the JD for your reference.

Job Description -

  • Own the end-to-end target security architecture across Microsoft Entra ID, Defender Suite (MDE, MDO, MDCA, MDI), Microsoft 365 Defender XDR, and Microsoft Purview (DLP, Insider Risk, eDiscovery, Information Protection, Compliance Manager).
  • Personally configure, test, and troubleshoot Conditional Access, Identity Protection, ASR rules, DLP policies, and sensitivity labels when required - particularly during initial deployment, escalations, or complex wave cutovers where deep technical credibility is needed.
  • Define enterprise-wide architectural standards for RBAC, cross-domain XDR correlation, and legacy tool decommissioning (CrowdStrike, Checkpoint EDR, Symantec DLP, Sophos).
  • Design the enterprise sensitivity label taxonomy, data governance model, and DLP control framework aligned to regulatory and business requirements.

Microsofte5 security at architect level at mentioned

Role Summary

We are seeking an experienced Director-level Security Architect to lead the design, governance, and technical direction of large-scale enterprise security transformation programs — with immediate responsibility for a major Microsoft E5 Security and Purview implementation for a global client. This is a working architect role, not a purely oversight position. The successful candidate must be equally comfortable presenting architecture strategy and risk trade-offs to client CISOs and board-level stakeholders, and rolling up their sleeves to configure, troubleshoot, and validate Microsoft E5 capabilities directly when delivery timelines, escalations, or technical complexity demand it. We are looking for a strong hands‑on practitioner with genuine prior delivery experience on the Microsoft E5 suite and to manage leadership‑level client relationships.

Key Responsibilities
1. Hands-On Architecture Leadership & Delivery
  • Own the end-to-end target security architecture across Microsoft Entra ID, Defender Suite (MDE, MDO, MDCA, MDI), Microsoft 365 Defender XDR, and Microsoft Purview (DLP, Insider Risk, eDiscovery, Information Protection, Compliance Manager).
  • Personally configure, test, and troubleshoot Conditional Access, Identity Protection, ASR rules, DLP policies, and sensitivity labels when required - particularly during initial deployment, escalations, or complex wave cutovers where deep technical credibility is needed.
  • Define enterprise-wide architectural standards for RBAC, cross-domain XDR correlation, and legacy tool decommissioning (CrowdStrike, Checkpoint EDR, Symantec DLP, Sophos).
  • Design the enterprise sensitivity label taxonomy, data governance model, and DLP control framework aligned to regulatory and business requirements.
  • Act as technical escalation point for Critical/High severity issues during stabilization and hypercare - diagnosing and resolving configuration issues directly alongside the delivery team, not just directing from above.
2. Program & Delivery Oversight
  • Lead architecture governance across all engagement phases and Knowledge Transfer.
  • Define wave exit criteria, oversee validation/testing activities, and sign off on architectural compliance before wave progression.
  • Step into delivery workstreams directly during resource gaps, tight deadlines, or high‑complexity configuration work to keep wave timelines on track.
3. Leadership-Level Client & Stakeholder Management
  • Act as the primary architectural point of contact for client CISO, IT leadership, and Business Unit stakeholders — building trusted‑advisor relationships at the most senior levels.
  • Present architecture decisions, risk trade‑offs, and roadmap progress confidently in board‑level and steering committee forums, translating technical complexity into business risk language.
  • Facilitate workshops with Business Units and Compliance teams to validate data classification, policy exceptions, and adoption impacts.
  • Manage difficult stakeholder conversations (scope, risk acceptance, delays) with composure and commercial judgment, protecting both client outcomes and our delivery integrity.
4. Team Leadership & Capability Building
  • Lead and actively work alongside a multi‑disciplinary delivery team (security engineers, consultants, project managers) across identity, endpoint, cloud app security, and data protection workstreams — leading from the front, including hands‑on configuration when needed.
  • Own quality assurance of technical deliverables: configuration baselines, SOPs, runbooks, stabilization/optimization reports, and KPI/health check reports.
  • Lead architecture‑focused Knowledge Transfer sessions and ensure client teams are enabled for independent BAU operation.
  • Contribute reusable architecture patterns and points of view to our Securing Emerging Technologies practice.
5. Risk, Compliance & Governance
  • Ensure architecture decisions strengthen regulatory compliance and audit readiness.
  • Balance security control rigor against business disruption - particularly for DLP, Insider Risk Management, and sensitivity labelling - via risk‑based tuning (Adaptive Protection).
  • Maintain architectural alignment with agreed scope boundaries and manage architecture‑impacting change requests through formal change control.
Required Qualifications & Experience
  • 15+ years in cybersecurity, with 8+ years in enterprise security architecture roles, ideally at Director/Principal Architect level in a consulting or large enterprise environment.
  • Proven, hands‑on prior delivery experience with the Microsoft E5 Security and Purview suite — this is a hard requirement, not a preference.
  • Candidates must be able to speak to specific configurations they have personally designed and deployed (e.g., Conditional Access policies, MDE/MDO/MDCA onboarding, DLP and sensitivity label rollouts, Insider Risk Management).
  • Demonstrated track record architecting AND delivering enterprise implementations at scale (10,000+ endpoints/servers, multi‑region) — not purely advisory engagements.
  • Deep hands‑on expertise across: Microsoft Entra ID (Conditional Access, Identity Protection, RBAC) Microsoft Defender Suite (MDE, MDO, MDCA/MCAS, MDI, Microsoft 365 Defender XDR)
  • Experience leading migration/consolidation from legacy/third‑party tools (e.g., CrowdStrike, Checkpoint, Symantec, Sophos) into unified Microsoft‑native platforms.
  • Demonstrated experience with wave‑based/phased enterprise rollouts, hypercare models, and formal stage‑gate/sign‑off governance.
  • Strong, evidenced ability to manage leadership‑level client stakeholders (CISO, CIO, Board/Steering Committee) — able to build trust quickly, navigate escalations, and influence senior decision‑makers.
  • Comfortable operating across the full spectrum from executive presentation to console‑level configuration within the same week — genuinely willing and able to roll up sleeves when delivery needs it.
  • Relevant certifications preferred: Microsoft Certified: Cybersecurity Architect Expert (SC-100), SC-200/SC-300/SC-400, CISSP, CISM, or TOGAF.
  • Experience in manufacturing, logistics, industrial, or critical infrastructure environments is highly valued given complexity of OT/IT convergence and heterogeneous device estates.
Key Skills

Technical Hands‑on Microsoft E5 Security & Purview configuration; Zero Trust architecture; XDR/SIEM integration patterns; DLP/data classification design; RBAC concepts

Delivery

Willingness and ability to execute hands‑on configuration/troubleshooting personally; multi‑region rollout governance; hypercare management

Leadership

Mentoring senior consultants; leading from the front on technical and client fronts simultaneously

Stakeholder Management

Executive/board‑level presentation; CISO/CIO relationship management; navigating escalations with composure and commercial judgment

Consulting

Proposal/SOW development; risk‑based prioritization; change management support

Domain

Regulatory compliance frameworks; industrial/manufacturing digital risk; emerging technology security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director Security Architect
Director Security Architect

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 5,000,000 - 8,000,000
Microsoft Security Architect-Freelancing
Microsoft Security Architect-Freelancing

InOpTra Digital • India

On-site
INR 2,500,000 - 3,500,000
Senior Manager - Information Security
Senior Manager - Information Security

Etenico Technologies • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Architect
Security Architect

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,500,000 - 5,500,000
Security Architect — Microsoft Security Platform
Security Architect — Microsoft Security Platform

Avanade • Bengaluru

Hybrid
INR 4,200,000 - 6,000,000
Information Technology Security Manager
Information Technology Security Manager

Advantmed India LLP • Pune District

Hybrid
INR 2,000,000 - 4,000,000
Architect - MWP
Architect - MWP

ValuePoint • Mumbai

On-site
INR 4,000,000 - 7,000,000
Security Architecture and ENGINEERING
Security Architecture and ENGINEERING

TOCUMULUS • Bengaluru

On-site
INR 1,600,000 - 2,400,000
Staff Security Architect
Staff Security Architect

KFC Corporation • Gurgaon

Hybrid
INR 1,800,000 - 2,500,000
IN_Senior Associate_MS Purview_ITRA_Advisory_Mumbai
IN_Senior Associate_MS Purview_ITRA_Advisory_Mumbai

PwC • Mumbai City

On-site
INR 4,000,000 - 7,000,000
Inclusive benefits
Mentorship programs
Flexibility programmes